skill-reviewer

Warn

Audited by Socket on Mar 18, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill's purpose and core capabilities are coherent, but it mandates transitive installation of a third-party skill from an unpinned GitHub source and runs local shell scripts. No clear credential theft or malicious exfiltration is present, so this is not malware, but the trust and supply-chain footprint is broader than necessary for a reviewer skill.

Confidence: 88%Severity: 63%
Audit Metadata
Analyzed At
Mar 18, 2026, 10:34 PM
Package URL
pkg:socket/skills-sh/niracler%2Fskill%2Fskill-reviewer%2F@9be87726f3928b33098f00b9bbc29a87d460305a